Aggregation Framework Vulnerability in MongoDB Server
CVE-2026-18704
7.1HIGH
What is CVE-2026-18704?
An issue within the MongoDB Server's aggregation framework allows authenticated users with only read privileges to execute write operations on collections unauthorized for them. This vulnerability arises from an internal aggregation stage being accessible to external clients without the needed authorization checks on its operations.
Affected Version(s)
MongoDB Server 8.3.0 < 8.3.8